Single passive identity agent monitoring multiple domain controllers
The diagram shows a standalone passive identity agent that monitors several AD domain controllers.
Architecture details
In this diagram, the standalone passive identity agent is installed on a client attached to the AD domain (or on the domain controller itself). Users log in to any domain controller and the agent sends user and IP address information to the Cloud-Delivered Firewall Management Center. As users access the network, access control and identity policies deployed to the Secure Firewall Threat Defense determine whether access is allowed and how access is permitted.
You can install a passive identity agent on the AD domain controller, directory server, or on any client connected to the domain you wish to monitor.